+1 646 851 2603

What Is FileMaker Secure Container Storage?

September 2, 2026

FileMaker container fields store documents, photographs, PDFs, videos, audio files, signatures and other binary content.

Container data may be embedded directly inside the FileMaker database or stored externally in a managed folder. When external storage is selected, FileMaker offers two methods:

  • Open storage
  • Secure storage

Secure container storage encrypts externally stored files and manages their names and locations so that they can be read through the FileMaker custom app rather than directly from the server’s file system.

Why store container data externally?

By default, container data can be embedded inside the .fmp12 database file. This is simple, but large quantities of embedded documents can make the database file much larger.

Claris recommends external storage for most container fields because it:

  • Keeps the FileMaker database smaller
  • Makes incremental backups more efficient
  • Improves performance for large media collections
  • Reduces the consequences of an interrupted container insertion
  • Centralizes container content on the host in a multiuser environment

If the insertion of a large embedded document is interrupted, the database file itself may be affected. With external storage, the potential damage is generally limited to the external object being written.

The reference linking the record to its container content remains inside the FileMaker database.

Open storage and secure storage

With open storage, externally stored files remain in their original format. A system administrator with access to the folder can normally see recognizable filenames, open the documents directly, and organize them according to a folder calculation defined in FileMaker.

This can be useful when another application or system process needs direct access to the files.

However, it also means that anyone who obtains access to the storage folder may be able to read the documents without authenticating through FileMaker.

With secure storage, FileMaker encrypts the external container data and controls its organization. The files cannot simply be opened from the server’s storage folder using their native applications.

Users access the content through FileMaker Pro, FileMaker Go, WebDirect or another authorized FileMaker interface, subject to the accounts and privileges defined in the custom app.

What risk does secure storage reduce?

Secure storage protects against unauthorized access to the container-data folder.

Without it, someone who copies or browses the external storage directory may be able to open invoices, identity documents, photographs, contracts or other sensitive files directly, without using a FileMaker account.

Secure storage helps protect against:

  • Unauthorized access to the server’s file system
  • Accidental exposure of the container directory
  • Theft or copying of external container storage
  • Users bypassing FileMaker privileges by opening files directly
  • Disclosure of filenames and folder structures
  • Reading container data separately from its FileMaker records

This complements FileMaker file encryption, which protects the .fmp12 database itself.

What risk does secure storage introduce?

Secure storage deliberately makes the external files dependent on FileMaker.

The files are no longer a conventional collection of readable documents with recognizable filenames. The FileMaker database contains the information required to associate each encrypted external object with the correct record and container field.

Consequently:

  • The database and its external container data must be backed up together.
  • The folder structure should not be renamed or reorganized manually.
  • Secure container files should not be moved using ordinary file-management tools.
  • A container folder without the corresponding database may be extremely difficult or impossible to use.
  • Damage to the database or loss of the relevant records may also make the associated container objects inaccessible.

Secure storage improves confidentiality, but reduces the ability to recover or reuse files independently of FileMaker.

This is why reliable backups must include both the database and its external container data.

The “With fewer folders” option

For secure external storage, FileMaker provides a With fewer folders option.

Traditional secure storage may distribute container objects across a large hierarchy of folders. This limits the number of files placed in each directory, but can make copying or moving a database and all its external container data slower.

The “With fewer folders” option reduces the number of directories created by FileMaker. This can make it considerably faster to:

  • Move a database to another server
  • Transfer its external container data
  • Copy the complete storage hierarchy
  • Perform maintenance involving large container collections
  • Migrate the custom app between hosting environments

For modern FileMaker deployments, we generally recommend selecting With fewer folders, particularly for databases that contain many externally stored files.

What is the trade-off?

The main limitation identified by Claris is compatibility.

The “With fewer folders” format is not compatible with older FileMaker clients and hosts. It should therefore be enabled only after confirming that every FileMaker Pro client and FileMaker Server installation accessing the file supports it.

Using fewer folders can also place more objects in each individual directory. Modern server file systems handle this well in most environments, but any change should still be tested with very large container collections and existing backup tools.

In practice, the decision is:

  • Use fewer folders for faster transfers and simpler modern deployments.
  • Keep the traditional folder structure when compatibility with older FileMaker versions is still required.

How do you enable secure external storage?

In FileMaker Pro:

  1. Choose File > Manage > Database.
  2. Open the Fields tab.
  3. Select the container field.
  4. Click Options.
  5. Open the Storage tab.
  6. Select Store container data externally.
  7. Choose Secure storage.
  8. Select With fewer folders when appropriate.

The external base directory can be managed through File > Manage > Containers.

Changing a field from embedded storage, open storage or another secure-storage structure does not instantly reorganize every existing object. Use Transfer Data in the Manage Containers dialog to transfer existing container content to the newly selected storage configuration.

Secure storage and FileMaker file encryption

When a FileMaker database is encrypted using Developer Utilities, externally stored container data is converted to secure storage by default.

The developer may select Keep Open Storage if the external files must remain directly readable outside FileMaker.

This choice should be deliberate. Keeping open storage preserves interoperability with external file-based processes, but means that those files do not receive the same protection as secure container storage.

See What Is FileMaker File Encryption? for the difference between database encryption, FileMaker user authentication and secure container storage.

Backing up external container data

An external container folder is part of the custom app’s data and must be included in its backup policy.

When FileMaker Server uses a separate container-data folder, administrators must ensure that the option to include that folder in backups is enabled. A backup of the .fmp12 file alone is not sufficient if the records refer to documents stored externally.

At fmcloud.fm, FileMaker Server backup schedules and externalized backups are configured to protect hosted databases and their managed container data. See the fmcloud.fm security policy and FileMaker Server Remote Backup for related information.

Access to the server, backups and FileMaker databases also involves several different credentials. They are explained in Which Password Should I Use with fmcloud.fm?.

Learn more

You may also like…

What Is FileMaker Standby Server?

FileMaker Standby Server is a business-continuity feature available as an optional add-on for FileMaker Server 2026....

15-day Free Hosting

Start your journey with us and discover fmcloud.fm now.